en un clic
Sec-Skills
Sec-Skills contient 5 skills collectées depuis boqiqibo, avec une couverture métier par dépôt et des pages de détail sur le site.
Skills dans ce dépôt
Analyze authorized Web applications that encrypt HTTP request or response payloads at the application layer, reconstruct their cryptographic and serialization pipeline, and design or implement a transparent plaintext inspection proxy for debugging or security testing. Use with captured traffic, JavaScript bundles, mobile/Web client code, or proxy requirements involving SM2, RSA, AES, hybrid encryption, signatures, custom encodings, mitmproxy, Burp Suite, or similar tooling.
漏洞严重性评分 Skill。根据用户描述的漏洞特征,使用简化三维评分体系(可达性、影响范围、利用复杂度)和 CVSS 3.1 标准进行漏洞严重性评估。适用于安全审计、渗透测试报告编写、漏洞定级等场景。当用户要求对漏洞进行评分、计算 CVSS 分数、确定严重等级时自动触发。
根据用户描述的网站特征和扫描需求,智能生成适合的 dirsearch 命令。当用户需要目录扫描、路径发现、敏感文件探测、Web 渗透测试侦察时使用此 skill。支持快速扫描、深度扫描、特定技术栈扫描、WAF 绕过等多种场景,每次提供至少 5 种命令选项供用户选择。
Analyze Flutter Android ARM64 libflutter.so to locate BoringSSL SSL_write/SSL_read function addresses and generate Frida SSL bypass scripts. Use this skill when the user mentions Flutter SSL analysis, BoringSSL function location, ecapture SSL hooking, libflutter.so reverse engineering, or needs to bypass Flutter SSL certificate verification.
通过MCP工具分析目标网站技术特征,生成符合FOFA、Hunter、Google语法规范的搜索语句,并明确各语句适用场景与预期搜索范围。